On 2026-09-21 11:02, Patrick Proniewski via Postfix-users wrote:
In a not too distant future I might have to bring back at home my email
self-hosted stack (Postfix, Dovecot, Webmail, all signing and
filtering…). It currently sits in a datacenter with a good reputation IP
address.
[snip]
I think signing (DKIM, ARC) at home, then forwarding to a postfix
instance on the VPS for public delivery, is not best practice.

There's debate about this. I'm on the side of signing on the originating server. Plus signing on the MX VPS means storing your signing key on someone else's computer.

I’m running FreeBSD. I’ve created a Jail with Wireguard client, a VPN
tunnel between the Jail and the Wireguard server on the VPS, but I could
not find a way to use that setup properly.

FWIW, I do this with the TLS secure channel capabilities of Postfix combined with certificate-based authentication, and separate inbound and outbound transports.

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to